Netskope Threat Labs

SERVER-WEBAPP Citrix NetScaler memory overread attempt

IPS-NPA

2 SIDs: 65118, 66199

Detects an attempt to exploit CVE-2025-5777, and CVE-2026-3055, a memory corruption flaw that can allow code execution or disclosure in Citrix NetScaler. The flaw, known as CitrixBleed 2.0, saw active exploitation to steal valid session tokens from NetScaler devices.